<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve &amp;quot;approaching the maximum number of historical searches&amp;quot; message received after moving to search head cluster? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213852#M62717</link>
    <description>&lt;P&gt;@sbattista09 - Were you able to find a solution to your question? If yes, was it somesoni2's link or GregMefford's answer? If no solution was found still, please feel free to leave a comment with more information.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2016 23:30:14 GMT</pubDate>
    <dc:creator>aaraneta_splunk</dc:creator>
    <dc:date>2016-11-28T23:30:14Z</dc:date>
    <item>
      <title>How to resolve "approaching the maximum number of historical searches" message received after moving to search head cluster?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213849#M62714</link>
      <description>&lt;P&gt;heyyyy everyone, anyone run into this annoying message before? &lt;/P&gt;

&lt;P&gt;we keep getting this after moving to a search head cluster&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;"The system is approaching the&lt;BR /&gt;
maximum number of historical searches&lt;BR /&gt;
that can be run concurrently.&lt;BR /&gt;
current=blahhh maximum=blahhahhh"&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 07 Nov 2016 18:37:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213849#M62714</guid>
      <dc:creator>sbattista09</dc:creator>
      <dc:date>2016-11-07T18:37:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "approaching the maximum number of historical searches" message received after moving to search head cluster?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213850#M62715</link>
      <description>&lt;P&gt;The &lt;CODE&gt;current&lt;/CODE&gt; number should be pretty straightforward to determine whether it's reasonable or not. The &lt;CODE&gt;maximum&lt;/CODE&gt; is normally determined roughly by the number of cores on the search head unless you have changed you parallelization settings ( &lt;CODE&gt;batch_search_max_pipeline&lt;/CODE&gt; setting in &lt;CODE&gt;limits.conf&lt;/CODE&gt;).&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.5.0/Capacity/Parallelization"&gt;http://docs.splunk.com/Documentation/Splunk/6.5.0/Capacity/Parallelization&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Maybe your SHC has less cores per server than your previously stand-alone Search Head?&lt;BR /&gt;
You can also look in the Distribute Management Center to see the number of concurrent historical searches over time.&lt;/P&gt;

&lt;P&gt;For example, if you open a dashboard with a dozen panels that are each running an independent search, that counts as 12.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213850#M62715</guid>
      <dc:creator>GregMefford</dc:creator>
      <dc:date>2016-11-07T20:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "approaching the maximum number of historical searches" message received after moving to search head cluster?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213851#M62716</link>
      <description>&lt;P&gt;See this&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/337598/search-head-cluster-pre-63-we-could-run-more-numbe-2.html"&gt;https://answers.splunk.com/answers/337598/search-head-cluster-pre-63-we-could-run-more-numbe-2.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2016 20:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213851#M62716</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-11-07T20:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve "approaching the maximum number of historical searches" message received after moving to search head cluster?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213852#M62717</link>
      <description>&lt;P&gt;@sbattista09 - Were you able to find a solution to your question? If yes, was it somesoni2's link or GregMefford's answer? If no solution was found still, please feel free to leave a comment with more information.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2016 23:30:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-resolve-quot-approaching-the-maximum-number-of-historical/m-p/213852#M62717</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-11-28T23:30:14Z</dc:date>
    </item>
  </channel>
</rss>

